Data Processing Agreement.
Last updated: August 5, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions between Unspam.email (“Unspam”, “we”, “us” or “our”) and the customer who accepts them (“Customer”, “you” or “your”). It applies whenever we process Personal Data on your behalf in the course of providing the Service.
This DPA takes effect when you accept the Terms and Conditions and requires no separate signature. If your procurement process needs a countersigned copy, write to dpo@unspam.email with the legal entity name and address it should be issued to.
Where we process Personal Data for our own purposes rather than yours, your account and billing details for example, or the visitor data described in our Privacy Policy, we act as a controller and that Policy governs instead of this DPA.
1. DEFINITIONS
- Applicable Data Protection Law: every law on the protection of Personal Data that applies to a party’s processing under this DPA, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the GDPR as retained in the law of the United Kingdom together with the Data Protection Act 2018 (“UK GDPR”), the Swiss Federal Act on Data Protection, and the privacy laws of United States states including the California Consumer Privacy Act as amended (“CCPA”).
- Customer Personal Data: Personal Data that we process on your behalf under this DPA. It includes the content of any email you submit for testing, the results our checks produce for it, and the account and support data of the individuals you authorise to use the Service.
- Controller, Processor, Data Subject, Personal Data, Personal Data Breach and Processing: as defined in the GDPR. In this DPA a reference to a controller includes a “business” and a reference to a processor includes a “service provider” as those terms are used in the CCPA.
- SCCs: the Standard Contractual Clauses for the transfer of Personal Data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021.
- UK Addendum: the International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner under section 119A(1) of the Data Protection Act 2018.
- Sub-processor: any processor we engage to process Customer Personal Data.
Terms not defined here have the meaning given in our Terms and Conditions or our Privacy Policy.
2. ROLES OF THE PARTIES
For Customer Personal Data you are the controller and we are your processor.
If you are yourself a processor for someone else, an agency testing email on behalf of its own client for instance, then you are a processor, we are your sub-processor, and you confirm that your own controller has authorised our engagement and the engagement of the sub-processors in Annex III. Everything in this DPA that we owe you, we owe on that basis.
Each party is separately responsible for its own compliance with Applicable Data Protection Law.
3. SCOPE AND DURATION OF PROCESSING
The subject matter, duration, nature and purpose of the processing, the categories of Personal Data and of Data Subjects, are described in Annex I. We process Customer Personal Data for as long as your contract with us is in force, and afterwards only as section 14 allows.
4. YOUR INSTRUCTIONS
We process Customer Personal Data only on your documented instructions. Your instructions are: this DPA, the Terms and Conditions, and your use of the features of the Service. We do not process Customer Personal Data for any purpose of our own, and in particular we do not use the content of the email you submit to train models of our own or to build profiles of you or of your recipients.
If we believe an instruction of yours would breach Applicable Data Protection Law, we will tell you and may suspend the affected processing until the instruction is withdrawn, amended or confirmed. If a legal obligation requires us to process Customer Personal Data beyond your instructions, we will tell you before we do so unless the law prohibits telling you.
You are responsible for the lawfulness of the Personal Data you submit and of your instructions to us, including for having a lawful basis for the processing, for any notice or consent your own recipients are owed, and for the accuracy of what you submit.
5. WHAT YOU SHOULD NOT SUBMIT
The Service exists to test how a message is treated by filters and mailbox providers, which almost never requires real recipient data. Submit the least Personal Data the test needs, and prefer your own seed and test addresses to live recipient lists.
Do not submit through the Service:
- special categories of Personal Data under Article 9 of the GDPR, meaning data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, data concerning health, or data concerning sex life or sexual orientation;
- Personal Data relating to criminal convictions and offences;
- government identifiers such as social security, passport or national identity numbers;
- payment card numbers, bank account details or other financial account credentials;
- Personal Data of children, or data subject to a sectoral regime we have not agreed in writing to support, such as protected health information under HIPAA.
The Service is not designed for these categories and we do not request them. If you need to test a message that carries them, redact or replace the values before you submit it. Where you submit such data despite this section, you do so outside the scope of this DPA and you remain responsible for it.
6. CONFIDENTIALITY AND PERSONNEL
We treat Customer Personal Data as confidential. We grant access to it only to personnel who need it to provide, support or secure the Service, those people are bound by confidentiality obligations that survive the end of their engagement, and access is withdrawn when it is no longer needed.
7. SECURITY MEASURES
We implement and maintain the technical and organisational measures described in Annex II, having regard to the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing as well as the risk to Data Subjects.
We may change a particular measure as technology and threats change, provided the overall level of security is not reduced.
You are responsible for the security decisions that sit on your side: keeping account credentials and API keys secret, removing access for people who leave, choosing who in your organisation may run tests and read results, and deciding what Personal Data you place in an email before you submit it.
8. SUB-PROCESSORS
You give a general written authorisation for us to engage sub-processors. The sub-processors engaged as at the date of this DPA are listed in Annex III, with what each one does and where it processes.
Before a sub-processor begins processing Customer Personal Data we impose on it, by contract, data protection obligations that are no less protective than those in this DPA, and we remain responsible to you for its performance as if the processing were our own.
We will give you at least 30 days’ notice before a new sub-processor starts processing Customer Personal Data, or before an existing one takes on a materially different role. To receive those notices, send the address they should go to to dpo@unspam.email. Within the notice period you may object on reasonable data protection grounds, in which case we will work with you in good faith to find a way to avoid the processing you object to. If we cannot, you may terminate the affected part of the Service by written notice, and we will refund any fees you have prepaid for a period after termination.
Where a change of sub-processor is needed urgently to protect the security or availability of the Service, we may make it immediately and will notify you without undue delay afterwards.
9. ASSISTANCE WITH DATA SUBJECT REQUESTS
The Service gives you the means to access, correct, export and delete the Customer Personal Data in your account yourself, which for most requests is the fastest route. Where a request cannot be handled that way, we will provide reasonable assistance, at your cost where the assistance goes beyond what the Service already offers.
If a Data Subject contacts us directly about Customer Personal Data, we will not respond to the substance of the request ourselves. We will tell the Data Subject to approach you and, where we can identify you, pass the request on without undue delay.
10. PERSONAL DATA BREACHES
We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent then known, the nature of the breach, the categories and approximate volume of Personal Data and Data Subjects concerned, the likely consequences, and the measures taken or proposed. If we cannot provide all of that at once, we will provide it in phases as it becomes available.
We will take reasonable steps to contain and remedy the breach, and will assist you with any notification you owe a supervisory authority or a Data Subject. Our notifying you is not an admission of fault.
11. IMPACT ASSESSMENTS AND AUDITS
On request we will give you the information you reasonably need to demonstrate compliance with this DPA, and reasonable assistance with a data protection impact assessment or a prior consultation with a supervisory authority, where these relate to our processing and you cannot obtain the information elsewhere.
You may audit our compliance with this DPA no more than once a year, unless Applicable Data Protection Law or a supervisory authority requires more, or unless we have notified a Personal Data Breach affecting you. An audit is subject to at least 30 days’ written notice, reasonable scope, working hours, confidentiality, and no access to another customer’s data or to anything that would compromise the security of the Service. Where a current third-party report or certification answers your question, providing it satisfies this section.
12. INTERNATIONAL TRANSFERS
We are established in the United States and Customer Personal Data is processed there, as our Privacy Policy states under PERSONAL DATA TRANSFER. One leg sits in the European Union: email you submit for testing is received by a mail server in Germany, operated by one of the providers listed in Annex III, and the message is processed there before and while the test runs.
Where you transfer to us Personal Data protected by the GDPR, the SCCs are incorporated into this DPA and apply as follows:
- you are the data exporter and we are the data importer;
- Module Two (controller to processor) applies where you are a controller, and Module Three (processor to sub-processor) applies where you are a processor acting for another controller;
- the optional docking clause in Clause 7 does not apply;
- in Clause 9, Option 2, general written authorisation, applies, with the notice period in section 8 above;
- in Clause 11, the optional independent dispute resolution paragraph does not apply;
- in Clause 17 the governing law is the law of Ireland, and in Clause 18(b) the forum is the courts of Ireland;
- Annexes I, II and III of this DPA populate Annexes I, II and III of the SCCs.
For Personal Data protected by the UK GDPR, the SCCs apply as amended by the UK Addendum, with the information required by its Tables taken from Annex I of this DPA, and with neither party able to end the Addendum under its Section 19 other than as the Addendum requires.
For Personal Data protected by Swiss law, the SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, with the Swiss Federal Data Protection and Information Commissioner as the supervisory authority, and with the clauses protecting legal entities to the extent Swiss law protects them.
If a transfer mechanism this DPA relies on is invalidated or superseded, we will without undue delay adopt an alternative lawful mechanism and that mechanism will apply in its place.
13. GOVERNMENT AND LAW ENFORCEMENT REQUESTS
If a public authority asks us to disclose Customer Personal Data, we will tell you unless we are legally prohibited from doing so, in which case we will use reasonable efforts to obtain a waiver of the prohibition and will record the steps we took. We will review each request for lawfulness, challenge one that appears unlawful or excessive, and disclose only the minimum the request actually requires.
14. DELETION AND RETURN
You may delete test results and other Customer Personal Data in your account at any time using the Service, and deleting your account deletes the Customer Personal Data in it.
On the end of your contract we will, at your choice, delete or return the Customer Personal Data we still hold, and delete any remaining copies, except to the extent Applicable Data Protection Law requires us to keep it. Where a copy persists in a backup taken before deletion, it stays subject to this DPA until the backup expires in the ordinary course.
15. UNITED STATES STATE PRIVACY LAWS
Where the CCPA or a comparable law of another United States state applies to Customer Personal Data, we act as your service provider or processor, and we do not:
- sell or share Customer Personal Data as those terms are defined in that law;
- retain, use or disclose it other than to provide the Service, or as that law otherwise permits a service provider;
- combine it with Personal Data received from anyone else, except as that law permits a service provider;
- use it for cross-context behavioural advertising.
We will notify you if we determine we can no longer meet these obligations, and we will grant you the right to take reasonable steps to confirm that we are using Customer Personal Data consistently with them.
16. LIABILITY, PRECEDENCE AND CHANGES
The limitations and exclusions of liability in our Terms and Conditions apply to this DPA, and to the SCCs to the extent the SCCs permit. Nothing in this DPA limits a Data Subject’s rights under the SCCs or under Applicable Data Protection Law.
If this DPA conflicts with the Terms and Conditions, this DPA prevails on the subject of the processing of Customer Personal Data. If this DPA conflicts with the SCCs, the SCCs prevail.
We may update this DPA where Applicable Data Protection Law, a supervisory authority or a decision of a court requires it, or to reflect a change in how the Service processes Customer Personal Data, provided the change does not reduce the protection this DPA gives Customer Personal Data. We will note the date of the current version at the top of this page.
17. CONTACT
For anything under this DPA, including sub-processor notices, a countersigned copy, an audit request or a data protection question:
- Email: dpo@unspam.email
ANNEX I: DESCRIPTION OF THE PROCESSING
A. The parties
Data exporter. The Customer: the entity that accepted the Terms and Conditions, identified by the account registered with the Service, with the contact details held in that account. Role: controller, or processor where section 2 applies. Activities relevant to the transfer: using the Service to test and analyse the deliverability of its own email.
Data importer. Unspam.email, 167 Madison Avenue, Suite 205, New York, NY 10016, United States, with a European location at Avenida Diagonal 82, pl. 8, 08019 Barcelona, Spain. Contact: dpo@unspam.email. Role: processor, or sub-processor where section 2 applies. Activities relevant to the transfer: providing the Service.
B. Description of the processing
Categories of Data Subject.
- the Customer’s own personnel and contractors who hold accounts on the Service or contact our support;
- senders and recipients identified in the email the Customer submits for testing, including anyone named or addressed in a message body;
- any other individual whose Personal Data the Customer chooses to include in a submitted message.
Categories of Personal Data.
- identification and contact data: first and last name, email address, company name, country, mailing address and phone number;
- the content of submitted email: subject line, headers including From, Reply-To, Return-Path and authentication headers, the HTML and plain-text bodies, and the links and images they reference;
- technical data in and around a submission: sending IP address, sending domain, authentication results and message identifiers;
- results we generate about a submission: filter scores, inbox placement, screenshots, heatmaps and the AI-generated report;
- support correspondence and its contents.
Special categories of Personal Data. None. The Service does not request them and section 5 instructs the Customer not to submit them.
Frequency of the transfer. Continuous, for as long as the Customer’s contract is in force.
Nature and purpose of the processing. Receiving, storing, rendering and automatically evaluating email the Customer submits, in order to report how filters and mailbox providers are likely to treat it and what to change; generating written reports about those results, including with the AI provider named in Annex III; maintaining the Customer’s account and subscription; and providing support.
Retention. For the duration of the contract, as described under PERSONAL DATA RETENTION in our Privacy Policy. A test result and the reports attached to it are deleted when the Customer deletes them or deletes the account. Content sent to the AI provider is subject in addition to the retention described under AI-GENERATED REPORTS in that Policy.
Transfers to sub-processors. To the sub-processors listed in Annex III, for the purposes described above and for as long as each one is engaged.
C. Competent supervisory authority
Where the Customer is established in the European Economic Area, the supervisory authority of the Member State of that establishment. Where the Customer is not established in the European Economic Area but has designated a representative under Article 27 of the GDPR, the authority of that representative’s Member State. Otherwise, the authority of the Member State in which the Data Subjects whose Personal Data is transferred are located.
ANNEX II: TECHNICAL AND ORGANISATIONAL MEASURES
These are the measures we apply to Customer Personal Data. They apply to sub-processors through the contractual obligations described in section 8.
- Encryption in transit. The website, the signed-in application and the API are served over HTTPS, and connections to sub-processors are encrypted in transit.
- Certified infrastructure. Customer Personal Data is stored with services and providers certified to ISO/IEC 27001:2013, PCI DSS, SOC 1 Type II and SOC 2 Type II or higher, which is also where encryption at rest and physical security are administered.
- Payment data never reaches us. Card details are entered with our payment sub-processor and are not stored in or transmitted through our systems. We hold only the billing contact details and the subscription record.
- Access control. Access to production data is limited to the personnel who need it, under individual named accounts rather than shared credentials, and is withdrawn when the need ends.
- Segregation between customers. Test results and the reports attached to them are bound to the account that created them, and one account cannot read another account’s results.
- Data minimisation in the AI path. Only the single test being reported on is sent to the AI sub-processor: the submitted message and the results of our own checks on it. Account identity, billing data and other tests are not sent.
- Deletion on request. Customers can delete individual test results and their account from within the Service, which deletes the Customer Personal Data those contain.
- Logging and error monitoring. Application errors and access to the Service are logged so that faults and misuse can be detected and investigated.
- Incident response. A Personal Data Breach is handled under section 10, including notification to the Customer and to authorities where the law requires it.
- Personnel. Everyone with access is bound by confidentiality obligations that survive the end of their engagement, as section 6 sets out.
- Sub-processor diligence. A sub-processor is engaged only under a written contract imposing protections no less protective than this DPA, and is listed in Annex III.
ANNEX III: SUB-PROCESSORS
These are the sub-processors we engage to process Customer Personal Data as at the date at the top of this page. Each operates under a written contract as described in section 8.
- OpenAI (OpenAI OpCo, LLC, United States): generation of the AI-written report on a test.
- ETH-Services (ETH-Services, Inh. Lennart Seitz, Germany): email hosting.
- Stripe (Stripe, Inc., United States): payment and subscription processing.
- Brevo (Sendinblue SAS, France): transactional and marketing email delivery.
- Help Scout (Help Scout PBC, United States): customer support correspondence.
- Sentry (Functional Software, Inc., United States): application error reporting.
- OVHcloud (OVH US LLC, United States): hosting and database infrastructure.
The measures in Annex II apply to each of them, through the contractual obligations in section 8. To confirm that this list is current before you rely on it, or to be told when it changes, write to dpo@unspam.email.
The providers we use for website analytics and consent measurement are not sub-processors under this DPA: they process visitor data for which we are the controller, and they are listed in our Privacy Policy and our Cookie Policy.